Legal
Data Processing Agreement ("DPA")
Last updated: 11 July 2026
1. Introduction
This Data Processing Agreement ("DPA") is entered into by and between the customer using the Services ("Client", "Customer", or "you") and DevSecure Ltd ("DevSecure", "Company", "we", "us", or "our").
This DPA forms part of the DevSecure Terms and Conditions, Terms of Service, Order Form, or other written agreement between Client and DevSecure that governs the use of the Services ("Agreement").
This DPA applies where DevSecure processes Personal Data on behalf of Client in connection with the DevSecure ASPM platform, DevSecure Intelligence platform, APIs, dashboards, integrations, support, and related services.
This DPA is effective when Client accepts the Agreement or uses the Services and remains in force for as long as DevSecure processes Client Personal Data.
If there is a conflict between this DPA and the Agreement, this DPA controls for data protection matters. If there is a conflict between this DPA and applicable Standard Contractual Clauses or UK transfer terms, those transfer terms control.
2. Definitions
"Applicable Data Protection Law" means all data protection and privacy laws that apply to the processing of Client Personal Data under the Agreement, including where applicable:
- the UK General Data Protection Regulation as incorporated into UK law;
- the Data Protection Act 2018;
- the EU General Data Protection Regulation 2016/679;
- the Privacy and Electronic Communications Regulations 2003;
- the California Consumer Privacy Act, as amended;
- any other applicable privacy, security, or data protection law.
"Client Personal Data" means Personal Data processed by DevSecure on behalf of Client under the Agreement.
"Controller", "Processor", "Data Subject", "Personal Data", "Personal Data Breach", "Process", "Processed", and "Processing" have the meanings given to them under Applicable Data Protection Law.
"Security Incident" means a confirmed breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorized disclosure of, or access to Client Personal Data processed by DevSecure.
"Services" means the DevSecure ASPM platform, DevSecure Intelligence platform, APIs, dashboards, integrations, vulnerability intelligence services, support services, and related products made available by DevSecure.
"Subprocessor" means any third party engaged by DevSecure to process Client Personal Data on behalf of DevSecure in connection with the Services.
"Sensitive Personal Data" means special category data, sensitive personal information, payment card data, government identification numbers, health data, biometric data, criminal offence data, or similar regulated data.
3. Roles of the Parties
For Client Personal Data processed under this DPA:
- Client is the Controller or Business.
- DevSecure is the Processor or Service Provider.
- DevSecure will process Client Personal Data only on Client's documented instructions, including the Agreement, this DPA, product configuration, API usage, support requests, and written instructions.
Client remains responsible for determining whether the Services are appropriate for its intended processing activities and for ensuring that Client has a lawful basis to submit Client Personal Data to DevSecure.
4. Scope and Purpose of Processing
DevSecure processes Client Personal Data to provide, secure, operate, monitor, support, and improve the Services.
This may include:
- account creation and authentication;
- organization and user access management;
- API key management;
- billing and subscription management;
- vulnerability prioritization and risk intelligence;
- ASPM, SAST, SCA, SBOM, cloud, container, IaC, and application security workflows where enabled;
- ingestion of vulnerability, asset, repository, package, scan, ticket, and remediation metadata;
- dashboards, reports, alerts, and customer support;
- security monitoring, fraud prevention, abuse prevention, and audit logging;
- service reliability, debugging, and incident response.
DevSecure will not process Client Personal Data for purposes unrelated to providing the Services.
5. Processing Restrictions
DevSecure shall:
- process Client Personal Data only in accordance with Client's documented instructions;
- comply with Applicable Data Protection Law as it applies to DevSecure as Processor;
- ensure that personnel authorized to process Client Personal Data are subject to confidentiality obligations;
- not sell Client Personal Data;
- not use Client Personal Data for targeted advertising;
- not combine Client Personal Data with data from other customers except where required to provide shared infrastructure, security, analytics, abuse prevention, or aggregated service metrics;
- not use Client Personal Data to train public AI models;
- not submit Client source code, secrets, credentials, or private repository content to AI model providers unless Client has enabled a feature that requires such processing and the relevant provider is listed as a Subprocessor;
- notify Client if DevSecure believes an instruction breaches Applicable Data Protection Law.
6. Client Obligations
Client shall:
- comply with Applicable Data Protection Law;
- ensure it has a lawful basis to provide Client Personal Data to DevSecure;
- provide all required notices to Data Subjects;
- obtain all required consents where consent is the lawful basis;
- configure the Services lawfully and securely;
- not submit Sensitive Personal Data unless expressly agreed in writing;
- not submit production secrets, passwords, private keys, access tokens, or credentials unless the relevant feature is specifically designed to store or process that data securely;
- ensure that Client users are authorized to use the Services.
7. Categories of Data Subjects
Client Personal Data may relate to:
- Client users and administrators;
- Client employees, contractors, consultants, and agents;
- security, engineering, DevOps, compliance, and management personnel;
- customers, end users, or other individuals whose data appears in assets, logs, tickets, repository metadata, vulnerability findings, support requests, or uploaded content.
8. Categories of Client Personal Data
The Services may process the following categories of Client Personal Data:
- names;
- business email addresses;
- usernames and account identifiers;
- organization names;
- role, team, and permission metadata;
- billing and subscription metadata;
- API usage metadata;
- IP addresses and device/browser metadata;
- audit logs and security logs;
- repository, package, commit, pull request, issue, ticket, and asset metadata;
- vulnerability finding metadata;
- support communications;
- any Personal Data Client submits through the Services.
DevSecure does not require Sensitive Personal Data to provide the Services. Client must not submit Sensitive Personal Data unless DevSecure has expressly agreed in writing.
9. Duration of Processing
DevSecure processes Client Personal Data for the duration of the Agreement and for any retention period required to provide the Services, comply with law, resolve disputes, enforce agreements, maintain security records, or meet audit requirements.
10. Deletion and Return
Upon termination of the Agreement, or upon Client's written request, DevSecure will delete or return Client Personal Data within a reasonable period, unless retention is required by law, security, backup, fraud prevention, audit, accounting, dispute resolution, or legitimate business record obligations.
Backup copies may remain in secure backup systems until overwritten according to DevSecure's backup retention schedule.
11. Security Measures
DevSecure will maintain appropriate technical and organizational measures designed to protect Client Personal Data.
These measures include, where applicable:
- encryption of data in transit;
- encryption of data at rest where supported by the relevant infrastructure;
- role-based access controls;
- least-privilege access;
- multi-factor authentication for administrative access;
- audit logging;
- security monitoring;
- vulnerability management;
- secure software development practices;
- code review and deployment controls;
- secret management controls;
- separation of production, staging, and development environments where appropriate;
- incident response procedures;
- backup and recovery controls;
- access revocation when personnel no longer require access;
- restrictions on agent or automation access to secrets;
- per-surface secret allow-lists for runtime environments;
- controls to prevent secrets from being copied between Cloud Run, Cloudflare Workers, build pipelines, and other runtime surfaces without authorization.
12. AI and Automated Processing
Where DevSecure uses AI-assisted features, DevSecure will apply security and privacy controls appropriate to the feature.
Unless Client has enabled a feature that requires AI processing, DevSecure will not intentionally send Client source code, private repository content, secrets, credentials, or Sensitive Personal Data to external AI model providers.
Where AI subprocessors are used, they must be listed in Exhibit C or otherwise disclosed to Client.
DevSecure does not use Client Personal Data to train public foundation models.
13. Subprocessors
Client authorizes DevSecure to use Subprocessors to provide the Services.
DevSecure will:
- maintain a list of current Subprocessors in Exhibit C or on a public subprocessor page;
- impose data protection obligations on Subprocessors that are substantially similar to this DPA;
- remain responsible for Subprocessor processing of Client Personal Data;
- notify Client of material Subprocessor changes where required by the Agreement or Applicable Data Protection Law.
If Client reasonably objects to a new Subprocessor on data protection grounds, Client must notify DevSecure in writing within 30 days of notice. The parties will work in good faith to resolve the objection. If no resolution is possible, Client may terminate the affected Services.
14. International Transfers
Where Client Personal Data is transferred from the United Kingdom, European Economic Area, Switzerland, or another jurisdiction with data transfer restrictions to a jurisdiction that does not provide adequate protection, DevSecure will use appropriate safeguards.
For transfers subject to the EU GDPR, the EU Standard Contractual Clauses, Module Two, Controller to Processor, apply where Client is the data exporter and DevSecure is the data importer.
For transfers subject to the UK GDPR, the UK International Data Transfer Addendum to the EU Standard Contractual Clauses applies.
For Swiss transfers, references to the EU GDPR and EU Member States will be interpreted as required to give effect to Swiss data protection law.
15. Data Subject Requests
If DevSecure receives a Data Subject request relating to Client Personal Data, DevSecure will, where legally permitted, direct the requester to Client or notify Client.
DevSecure will provide reasonable assistance to Client in responding to Data Subject requests where Client cannot reasonably respond using the Services.
Client is responsible for verifying the request, determining the appropriate response, and communicating with the Data Subject unless otherwise required by law.
16. Data Protection Impact Assessments
DevSecure will provide reasonable assistance to Client with data protection impact assessments, transfer risk assessments, consultations with supervisory authorities, and similar compliance obligations where required by Applicable Data Protection Law and where the information is available to DevSecure.
17. Audits
DevSecure will maintain records sufficient to demonstrate compliance with this DPA.
Upon reasonable written request, DevSecure will provide information necessary to demonstrate compliance, which may include security summaries, audit reports, policies, questionnaires, or certifications where available.
Client may request an audit no more than once per year unless required by law or following a Security Incident. Audits must be conducted during normal business hours, with reasonable notice, and must not compromise DevSecure's security, confidentiality, other customers, systems, or operations.
18. Confidentiality
DevSecure will ensure that personnel who process Client Personal Data are subject to confidentiality obligations.
19. Security Incident Notification
DevSecure will notify Client without undue delay after becoming aware of a Security Incident affecting Client Personal Data.
The notice will include, where available:
- nature of the Security Incident;
- categories of Client Personal Data affected;
- likely consequences;
- measures taken or proposed to address the Security Incident;
- information reasonably required for Client to meet its legal obligations.
DevSecure may provide information in phases as investigation progresses.
20. Third-Party Requests
DevSecure will notify Client of any legally binding request for disclosure of Client Personal Data by a public authority unless legally prohibited.
DevSecure will challenge or limit requests where it has reasonable grounds to do so and where legally permitted.
21. Liability
Each party is responsible for its own compliance with Applicable Data Protection Law.
Liability under this DPA is subject to the limitations and exclusions in the Agreement, except where such limitations are prohibited by Applicable Data Protection Law.
22. Order of Precedence
If there is a conflict between the Agreement and this DPA, this DPA controls for data protection matters.
If there is a conflict between this DPA and applicable SCCs, UK Addendum, or other mandatory transfer terms, those transfer terms control.
23. Contact
Privacy contact: privacy@devsecure.io
Security contact: security@devsecure.io
Legal entity: DevSecure Ltd
Registered office: Nelson House, Twickenham, London TW2 7BW
Company number: 4946160
Exhibit A, Details of Processing
A. Parties
Data Exporter
Name: The Client accepting the Agreement.
Role: Controller.
Address: As provided by Client in its account, Order Form, or Agreement.
Activities: Use of DevSecure Services for application security, vulnerability intelligence, ASPM, API access, dashboards, reporting, and related workflows.
Contact: As provided by Client.
Signature: By accepting the Agreement or using the Services, Client is deemed to have signed this DPA.
Data Importer
Name: DevSecure Ltd
Role: Processor.
Address: Nelson House, Twickenham, London TW2 7BW
Activities: Provision, operation, support, security, monitoring, and improvement of the Services.
Contact: privacy@devsecure.io
Signature: By providing the Services, DevSecure is deemed to have signed this DPA.
B. Description of Processing
Subject Matter: Processing of Client Personal Data in connection with the provision of the Services.
Nature of Processing: Collection, receipt, storage, hosting, transmission, analysis, organization, retrieval, access, display, deletion, support, monitoring, and security processing.
Purpose: To provide DevSecure ASPM, DevSecure Intelligence, vulnerability prioritization, API services, dashboards, authentication, billing, alerts, reporting, integrations, and customer support.
Frequency: Continuous for the duration of the Agreement.
Retention: For the duration of the Agreement and any period required by law, security, backup, audit, billing, dispute resolution, or legitimate business record obligations.
Categories of Data Subjects: Client users, administrators, employees, contractors, security teams, engineering teams, DevOps personnel, compliance teams, and individuals whose Personal Data is included in content submitted by Client.
Categories of Personal Data: Names, email addresses, usernames, organization identifiers, role metadata, access permissions, billing metadata, API usage metadata, IP addresses, device metadata, support communications, vulnerability metadata, repository metadata, package metadata, asset metadata, log metadata, ticket metadata, and content submitted by Client.
Sensitive Personal Data: None expected. Client must not submit Sensitive Personal Data unless expressly agreed in writing.
Competent Supervisory Authority: For UK GDPR matters, the UK Information Commissioner's Office. For EU GDPR matters, the supervisory authority determined under the applicable SCCs and the Client's establishment or representative arrangements.
Exhibit B, Technical and Organizational Measures
DevSecure maintains a risk-based security program. Measures may include:
1. Access Control
- least-privilege access;
- role-based access;
- MFA for administrative systems;
- access reviews;
- prompt access removal when access is no longer required.
2. Encryption
- TLS for data in transit;
- encryption at rest where supported by infrastructure providers;
- managed secret storage for production credentials.
3. Secret Management
- secrets are scoped to the runtime surface that needs them;
- secrets must not be copied across Cloud Run, Cloudflare Workers, pipelines, or Kubernetes workloads without approval;
- deployment agents must verify secret allow-lists before deployment;
- secrets must not be committed to source control.
4. Logging and Monitoring
- application logs;
- API logs;
- security logs;
- operational monitoring;
- alerting for relevant failures and suspicious activity.
5. Secure Development
- code review;
- dependency management;
- vulnerability scanning;
- secret scanning;
- testing before deployment;
- separation of development and production workflows where appropriate.
6. Infrastructure Security
- hardened cloud infrastructure;
- access-controlled production systems;
- infrastructure provider physical security;
- network and application-layer protections where configured.
7. Incident Response
- incident triage;
- containment;
- investigation;
- remediation;
- customer notification where required.
8. Availability and Recovery
- backup controls where applicable;
- disaster recovery planning appropriate to service maturity;
- operational monitoring;
- restoration processes for supported services.
9. Personnel Controls
- confidentiality obligations;
- security awareness;
- limited access based on job need;
- offboarding procedures.
Exhibit C, Subprocessors
The following list must be verified before publication. Remove any provider not used in production. Add any provider that processes Client Personal Data.
Current or expected Subprocessors:
1. Google Cloud Platform
Service: Cloud hosting, Cloud Run, storage, databases, logging, infrastructure Location: Global, including UK, EU, and USA depending on configuration
2. Cloudflare
Service: DNS, CDN, WAF, Workers, API routing, edge security Location: Global
3. Clerk
Service: Authentication, user management, organization management Location: USA / global
4. Stripe
Service: Payment processing, subscriptions, billing portal Location: USA / global
5. Brevo
Service: Transactional email and customer communications Location: EU / global
6. Better Stack
Service: Logging, monitoring, observability, incident alerts Location: EU / global
7. Hetzner
Service: Server hosting for pre-production or production infrastructure where enabled Location: Germany / EU
8. OpenRouter
Service: AI model routing for SAST or AI-assisted features where enabled Location: USA / global
9. e2b.dev
Service: Secure execution sandbox for AI-assisted SAST workflows where enabled Location: USA / global
10. PostHog
Service: Product analytics, only if enabled Location: USA / EU depending on configuration
11. Slack
Service: Internal operational notifications and support workflow, only if customer data is sent through support or alerting workflows Location: USA / global
Subprocessor Change Notice:
DevSecure may update this list from time to time. DevSecure will notify Clients of material changes as required by the Agreement or Applicable Data Protection Law.
Client Objection:
Client may object to a new Subprocessor on reasonable data protection grounds. If the parties cannot resolve the objection, Client may terminate the affected Services.